A certificate proves one thing: that what was in scope met the standard on the day of the audit.
Then the auditor comes back. Once a year for a surveillance visit, and every third year for recertification. Each visit asks the same question in a different depth: is what was in scope still working?
What the auditor is actually testing
A surveillance visit is a sample, but not a random one. Certification bodies are required to look every year at the parts of the system that show whether it is alive: the internal audit programme and its results, the management review, what happened to the nonconformities raised last time, complaints, progress against objectives, and anything that has changed in the organisation or its scope. The rest of the standard is sampled across the cycle.
Recertification looks at the whole system and at the cycle as a whole. The question is no longer whether each clause is met today, but whether the system has run as a system for three years.
In both cases the auditor is looking for evidence that:
- the scope still describes the organisation as it is now, not as it was when the certificate was first issued;
- risks have been reviewed as the business, its suppliers and the threat picture changed, and the agreed treatments actually happened;
- internal audits produced findings that were closed, not filed;
- management reviews took place, with decisions recorded and followed through;
- objectives were set, measured and acted on.
None of these is about paperwork. Each is about whether the thing is working.
The standards have a word for this: effectiveness, defined as the extent to which planned activities are carried out and planned results achieved. Clause 9.1 of every management system standard asks you to measure it. Control metrics feed that judgement, but no number of them adds up to it on their own. Effectiveness is a judgement about the system as a whole, and it is exactly what the auditor is there to form a view on.
Two positions, one visit
Every certified organisation receives the auditor in one of two positions.
Certified, and able to prove it is working. Every requirement has been assessed on how well it achieves its purpose, not just whether a document exists. Gaps surfaced during the year and were closed. When the auditor asks "how do you know?", someone can answer with evidence.
Certified, but unable to say for sure. The certificate is on the wall. The documents exist, most of them dated from the last visit. The honest answer to "is it working?" is that nobody has measured it since.
The second position is more common than people admit, and it is not a failure of effort. It is what happens when compliance is run as a project with an end date rather than as a discipline with a rhythm.
Six things to do before the visit
If an audit is within three months, these six steps change the outcome more than anything else.
- Re-read the scope against today's organisation. New offices, new services, new suppliers, cloud moves and restructures all change what the certificate covers. An out-of-date scope is the fastest route to a finding.
- Close the loop on the last visit. Every finding, corrective action and management review action since then should be demonstrably closed, with evidence, or consciously carried forward with a reason. The auditor will start here.
- Run the internal audit the way the auditor will. Cover the clauses due this cycle, and do not avoid the hard ones. Score each requirement on how well it achieves its purpose, from fully effective through to not operating, rather than ticking presence. The scores tell you where to spend the remaining weeks.
- Hold a management review that decides things. Minutes that record attendance and nothing else are a finding waiting to happen. The review should look at performance, risks, audit results and objectives, and record decisions with owners and dates.
- List what has changed since the last visit. New systems, new suppliers, incidents, legal or regulatory changes, changes to the standard itself. The auditor will ask what changed and what you did about it. Have the answer written down before they do.
- Rehearse with the people who will be in the room. The auditor talks to control owners, not to the compliance lead. Each person should know which evidence they hold, where it is, and how to explain what they actually do, in their own words.
What good looks like
Organisations that walk into an audit without anxiety have one thing in common. They were measuring effectiveness between visits, not just inspecting the system during them. Nothing the auditor finds is a surprise, because it was found first, internally, and dealt with.
That is not a ninety-day exercise. It is a rhythm. But ninety days is enough to find out which position you are in, and to do something about it.
If the auditor is back
If a visit is on your calendar and you are not sure which position you are in, that is worth knowing before the auditor does. Thirty minutes with a practitioner will usually tell you, with no proposal at the end of the call.
If you would rather start on your own, the free Readiness Check gives an indicative SSF Effectiveness Score in minutes, with no documents required.
Not sure which position you are in?
Talk to a practitioner, thirty minutes with no proposal at the end, or start with the free Readiness Check.